From owner-freebsd-audit Wed Apr 25 10:57: 8 2001 Delivered-To: freebsd-audit@freebsd.org Received: from fledge.watson.org (fledge.watson.org [204.156.12.50]) by hub.freebsd.org (Postfix) with ESMTP id 7279437B42C for ; Wed, 25 Apr 2001 10:57:05 -0700 (PDT) (envelope-from arr@watson.org) Received: from localhost (arr@localhost) by fledge.watson.org (8.11.3/8.11.3) with SMTP id f3PHvXI38596 for ; Wed, 25 Apr 2001 13:57:34 -0400 (EDT) (envelope-from arr@watson.org) Date: Wed, 25 Apr 2001 13:57:33 -0400 (EDT) From: "Andrew R. Reiter" To: freebsd-audit@freebsd.org Subject: audit work: more setenv checking Message-ID: MIME-Version: 1.0 Content-Type: TEXT/PLAIN; charset=US-ASCII Sender: owner-freebsd-audit@FreeBSD.ORG Precedence: bulk X-Loop: FreeBSD.ORG hi, after quickly fixing the kerberosIV setenv() calls, I just grep'd for setenv() and found a couple in libutil's login_class.c. in the patch, I handle alittle bit of some free()'ing of allocated space, but I'd enjoy someone who has done a bit more work with libutil to check it out. the patch is at: http://www.watson.org/~arr/fbsd-audit/lib/libutil/login_class.c.04252001.diff thanks, Andrew *-------------................................................. | Andrew R. Reiter | arr@fledge.watson.org | "It requires a very unusual mind | to undertake the analysis of the obvious" -- A.N. Whitehead To Unsubscribe: send mail to majordomo@FreeBSD.org with "unsubscribe freebsd-audit" in the body of the message